A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
On an error when building a nftables rule, deactivating immediate expressions in nft_immediate_deactivate() can lead unbinding the chain and objects be deactivated but later used.
We recommend upgrading past commit 0a771f7b266b02d262900c75f1e175c7fe76fec2.
| Software | From | Fixed in |
|---|---|---|
| debian / debian_linux | 12.0 | 12.0.x |
| linux / linux_kernel | 6.2 | 6.4.8 |
| linux / linux_kernel | 5.16 | 6.1.43 |
| linux / linux_kernel | 5.11 | 5.15.124 |
| linux / linux_kernel | 5.9 | 5.10.190 |